Privacy Policy
Last updated: June 9, 2026
1. Who We Are
Forecraft (“Forecraft,” “we,” “us,” or “our”) operates the financial close workflow platform available at forecraft.tech.
ForeCraft is a financial close workflow platform. For GDPR purposes, see the contact address below. Legal entity details will be updated upon formal incorporation.
For GDPR purposes, Forecraft acts as a data processor with respect to the financial data you upload on behalf of your clients, and as a data controller with respect to your account data and usage data.
2. What Data We Collect
Data you provide directly
- Account data
- Name, email address, and password (stored as a bcrypt hash — never in plain text).
- Workspace and firm settings
- Firm name, client workspace names, brand colors, logo, accounting method preferences, and other configuration you set up within the Service.
- Financial data
- Profit & loss files, balance sheets, budget files, and any other financial documents you upload or that Forecraft pulls from accounting integrations on your request. This is your clients’ financial data — you retain ownership of it.
- Payment data
- Payment processing is handled entirely by Stripe. We store only your Stripe Customer ID and Subscription ID. We never store your card number, bank account details, or any payment credentials.
- Communications
- Emails you send to our support or privacy addresses, feedback submitted through the Service, and any other communications with us.
Data collected automatically
- Usage data
- Pages visited, features used, actions taken within the Service, and timestamps. Usage logs do not contain the content of your financial data — only interaction events (e.g., “report generated,” “file uploaded”).
- Authentication and security logs
- Login times, IP addresses, and device information. Retained for 90 days for security and fraud prevention purposes.
- Technical data
- Browser type, operating system, and device type, used to ensure compatibility and investigate errors.
Data from integrations
- QuickBooks Online / Xero
- If you connect an accounting integration, Forecraft retrieves financial reports (P&L, balance sheets) from that integration on your explicit request. OAuth tokens that authorize this access are encrypted at rest. You may disconnect an integration at any time from Settings.
3. How We Use Your Data
- Account data
- To create and manage your account, authenticate you, and communicate with you about your subscription and the Service.
- Financial data
- To generate close packs, variance analysis, and management reports — the core purpose of the Service. Financial data is processed only to provide these features to you.
- AI processing
- When you use AI-powered features (executive narrative, variance explanations), relevant financial data is sent to Anthropic’s API to generate the requested text. This data is processed for that request only. Anthropic’s API terms prohibit using API inputs to train or improve their models without customer consent — we have not granted that consent. See Anthropic’s Privacy Policy for their practices.
- Authentication logs
- To detect and prevent unauthorized access to your account. Retained for 90 days.
- Usage data
- To understand how the Service is used and to improve features and performance. This data is aggregated and not linked to specific financial data.
- Payment data
- Processed by Stripe to manage subscriptions and billing. We receive confirmation of payment status only.
- Communications
- To respond to your support requests and to send transactional communications (account verification, password reset, billing notifications).
4. How We Do Not Use Your Data
We want to be explicit about what we do not do:
- We do not sell your personal data or your clients’ financial data.
- We do not use financial data to train any AI model — Forecraft’s or anyone else’s.
- We do not share your data with advertisers or ad networks.
- We do not build profiles of you or your clients for advertising or marketing purposes.
- We do not use your clients’ financial data for any purpose other than providing the Service to you.
5. Data Sharing and Sub-Processors
We share data only with the service providers necessary to operate the Service (“sub-processors”). All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security.
- Vercel — Hosting and infrastructure
- Our application runs on Vercel’s platform (United States). Financial data passes through Vercel’s servers to reach our database.
- Neon — Database
- Your financial data, account data, and workspace data are stored in Neon’s PostgreSQL database (United States). Database connections are encrypted.
- Anthropic — AI narrative generation
- Financial data is sent to Anthropic’s API only when you use AI features, and only for that request. Data is minimized to what is necessary for the feature.
- Stripe — Payment processing
- Billing data is processed by Stripe. We do not receive or store raw payment credentials. Subject to Stripe’s Privacy Policy.
- Upstash — Rate limiting and session management
- Used for Redis-based rate limiting on authentication routes. Does not store financial data.
- Resend — Transactional email
- Used to send verification emails, password resets, and billing notifications. Email addresses are shared only for delivery.
- Sentry — Error monitoring
- Application errors are reported to Sentry for debugging. Error reports are scrubbed of financial data before transmission.
Sub-processor details
| Sub-processor | Role | Data location | EU transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Hosting & infrastructure | United States | Standard Contractual Clauses |
| Neon Inc. | Database (PostgreSQL) | United States | Standard Contractual Clauses |
| Anthropic PBC | AI narrative generation | United States | Standard Contractual Clauses |
| Stripe Inc. | Payment processing | United States | Standard Contractual Clauses |
| Upstash Inc. | Rate limiting & caching | United States | Standard Contractual Clauses |
| Resend Inc. | Transactional email | United States | Standard Contractual Clauses |
Legal disclosures
We may disclose your data if required to do so by law, court order, or government authority. Where permitted, we will notify you before complying with such a request.
Business transfers
If Forecraft is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
6. Data Retention
- Account and financial data
- Retained while your account is active, plus 30 days after cancellation or termination to allow data export. After 30 days, permanently deleted.
- Authentication and security logs
- Retained for 90 days, then automatically purged.
- Deleted workspace data
- Removed from active systems within 30 days of deletion and from backup systems within 90 days.
- Stripe payment records
- Retained per Stripe’s own data retention policies.
7. Your Rights
All users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion:Request deletion of your account and all associated data. Use “Delete account” in Account Settings or email privacy@forecraft.tech.
- Export: Download all your data at any time from Account Settings.
- Portability: Receive your data in a machine-readable format on request.
GDPR — EEA and UK users
If you are located in the European Economic Area or the United Kingdom, you also have:
- The right to restrict processing of your personal data.
- The right to object to processing based on legitimate interests.
- The right not to be subject to automated decision-making with significant effects.
- The right to lodge a complaint with your local supervisory authority.
Legal basis for processing: (a) contract performance — to provide the Service; (b) legitimate interests — for security and service improvement; (c) legal obligation — where required by law.
Legal basis for processing (GDPR Article 6)
For users in the European Union, ForeCraft processes personal data under the following legal bases:
- Contract performance (Article 6(1)(b))
- Processing your account data, workspace data, and payment information is necessary to provide the ForeCraft service you have contracted for.
- Legitimate interests (Article 6(1)(f))
- Processing authentication logs and security monitoring data is necessary for our legitimate interest in securing the platform and preventing unauthorized access.
We do not process data on the basis of consent except for non-essential analytics cookies where you have explicitly opted in via the cookie consent banner.
CCPA — California users
- Right to know what personal information we collect.
- Right to delete your personal information.
- Right to opt out of sale — we do not sell personal information.
- Right to non-discrimination for exercising CCPA rights.
To exercise any rights, contact privacy@forecraft.tech. We respond within 45 days for CCPA requests and 30 days for GDPR requests.
8. Cookies and Tracking
- Session cookies
- Required for authentication. Expire when you close your browser or after 30 days.
- Preference cookies
- Store UI settings such as workspace selection.
We do not use advertising cookies, third-party tracking cookies, or behavioral profiling.
A cookie consent banner is shown on first visit. You may accept essential cookies only, or opt in to analytics. Your preference is stored for 12 months.
9. Data Security
- Encryption in transit: TLS 1.3.
- Encryption at rest: AES-256.
- Passwords hashed with bcrypt (cost factor 12) — never stored in plain text.
- OAuth tokens for integrations encrypted at rest.
- Workspace isolation — users in one workspace cannot access another.
- Two-factor authentication (TOTP) available for all accounts.
- Rate limiting on authentication endpoints.
- Regular security reviews.
Breach notification: We will notify you of a breach affecting your data without undue delay and within 72 hours where required by GDPR. See our Security page for full detail.
10. International Data Transfers
Forecraft’s infrastructure is located in the United States. If you access the Service from the EEA, UK, or another jurisdiction with data transfer restrictions, your data will be transferred to and processed in the United States.
International transfers from the EEA and UK are made under Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021/914). A copy of the applicable SCCs is incorporated into our Data Processing Addendum. For UK users, transfers comply with the UK International Data Transfer Agreement (IDTA).
11. Children
Forecraft is not directed to individuals under 18. We do not knowingly collect data from minors. Contact privacy@forecraft.tech if you believe we have collected data from a minor.
12. Contact for Privacy
13. Changes to This Policy
We will notify you of material changes by email at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.
Last updated: June 9, 2026
See also: Terms of Service · Acceptable Use Policy · Data Processing Addendum · Security · Plain-English Data Guide